Skip to main content

sumologic-netskope-collector

Solution to pull data from Netskope to Sumo Logic

Installation

  1. Getting a token from Netskope portal

    • Login to Netskope as the Tenant Admin. Netskope REST APIs use an auth token to make authorized calls to the API. The token can be obtained from the UI by following the below steps
    • Go to the API portion of the Netskope UI ( Settings > Tools > Rest API)
    • Copy the existing token to your clipboard Alternatively, you can generate a new token and copy that
  2. Add a Hosted Collector and HTTP Source

    • To create a new Sumo Logic Hosted Collector, perform the steps in Configure a Hosted Collector.
    • Add an HTTP Logs and Metrics Source. Under Advanced you'll see options regarding timestamps and time zones and when you select Timestamp parsing specify the custom time stamp format as shown below: Format: epoch Timestamp locator: \"timestamp\": (.*),
  3. Configuring the sumologic-netskope collector Below instructions assume pip is already installed if not then, see the pip docs on how to download and install pip.

    sumologic-netskope-collector is compatible with python 3.7 and python 2.7. It has been tested on ubuntu 18.04 LTS and Debian 4.9.130. Login to a Linux machine and download and follow the below steps:

    • Install the collector using below command pip install sumologic-netskope-collector

    • Create a configuration file netskope.yaml in home directory using the sample.yaml file(in sumologic-netskope folder). Add the SUMO_ENDPOINT and TOKEN parameters obtained from step 1 and step 2 and replacing the "netskope domain" variable with your Netskope portal domain.

      SumoLogic:
        SUMO_ENDPOINT: <SUMO LOGIC HTTP URL>
      
      
      Netskope:
        TOKEN: <NETSKOPE API TOKEN>
        NETSKOPE_EVENT_ENDPOINT: <netskope domain>/api/v1/events
        NETSKOPE_ALERT_ENDPOINT: <netskope domain>/api/v1/alerts
      
      
      
    • Create a cron job for running the collector every 5 minutes by using the crontab -e and adding the below line */5 * * * * /usr/bin/python -m sumonetskopecollector.netskope > /dev/null 2>&1

Release files for sumologic-netskope-collector 1.0.10

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for sumologic-netskope-collector 1.0.10
File Size Uploaded
sumologic-netskope-collector-1.0.10.tar.gz 10.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for sumologic-netskope-collector 1.0.10
File Interpreter ABI Platform
sumologic_netskope_collector-1.0.10-py3-none-any.whl Python 3 none any Details

Total release size: 22.0 kB

Release files / sumologic-netskope-collector-1.0.10.tar.gz

Download URL sumologic-netskope-collector-1.0.10.tar.gz
Size 10.6 kB
Tags Source
SHA-256 checksum
How to use checksums
4e78e83daa0e11c1b194946a53a4cc35f971da50bf83379b4f39fe584f547aac
BLAKE2b-256 checksum
How to use checksums
7eb3fb8dddbb926b6d4e252ca07d897166c8d6c6a9838c71b2103c583f655e0c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.2.0 pkginfo/1.6.1 requests/2.25.0 setuptools/41.2.0 requests-toolbelt/0.9.1 tqdm/4.54.1 CPython/3.8.0

Release files / sumologic_netskope_collector-1.0.10-py3-none-any.whl

Download URL sumologic_netskope_collector-1.0.10-py3-none-any.whl
Size 11.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
780abcaed5a9f74b9fbac30110289a14c037a6a3f62fd20bf7c691703bf6497e
BLAKE2b-256 checksum
How to use checksums
31417607d1af1c9e52c3546cd38cef73f5fa99e33d2d6bd97ff3380374fb8ae7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.2.0 pkginfo/1.6.1 requests/2.25.0 setuptools/41.2.0 requests-toolbelt/0.9.1 tqdm/4.54.1 CPython/3.8.0

Release history Release notifications | RSS feed

This release

1.0.10 This release

2 release files

1.0.9

2 release files

1.0.8

2 release files

1.0.7

2 release files

1.0.6

2 release files

1.0.5

2 release files

1.0.4

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page